MGASA-2014-0423
Dashboard / Vulnerabilities / MGASA-2014-0423
Summary: Updated drupal packages fix security vulnerability
Details: An SQL Injection issue exists in Drupal before 7.32 due to the way the Drupal core handles prepared statements. A malicious user can inject arbitrary SQL queries, and thereby completely control the Drupal site. This vulnerability can be exploited by remote attackers without any kind of authentication required (CVE-2014-3704).
References: https://advisories.mageia.org/MGASA-2014-0423.html, https://bugs.mageia.org/show_bug.cgi?id=14298, https://www.drupal.org/SA-CORE-2014-005, https://www.drupal.org/drupal-7.32, https://www.drupal.org/drupal-7.32-release-notes, http://www.sektioneins.com/en/advisories/advisory-012014-drupal-pre-auth-sql-injection-vulnerability.html, http://www.debian.org/security/2014/dsa-3051
Affected packages
Package
Name: drupal
Purl: pkg:rpm/mageia/drupal?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
